Report Date: 2026-07-30
New KEVs: 3 ▼ -3 vs last weekRansomware Victims: 230 ▲ +52 vs last week
3 vulnerabilities were added to the CISA Known Exploited Vulnerabilities catalog this period. Cisco products show the strongest concentration of risk signals this week. Threat intelligence sources this period reference Lazarus Group (DPRK). Ransomware activity is moderate with 230 new victims posted to leak sites over the last 7 days, with Qilin posting the most victims.
Patch This Week
The top 3 KEVs to remediate right now, ranked by CISA deadline proximity, ransomware exploitation, and severity. These are confirmed exploited — if you do nothing else today, patch these.
- CVE-2026-16812 – Arista VeloCloud Orchestrator | CVSS 10.0 | EPSS 0.9% / 56th pct
CISA deadline: 2026-07-30 (0d remaining) — Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines. - CVE-2026-20316 – Cisco Secure Firewall Management Center (FMC) | CVSS 5.3 | EPSS 0.8% / 53th pct
CISA deadline: 2026-08-01 (2d remaining) — Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines. - CVE-2025-68686 – Fortinet FortiOS | CVSS 5.9 | EPSS 1.3% / 67th pct
CISA deadline: 2026-08-10 (11d remaining) — Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
Top KEVs
Vulnerabilities confirmed actively exploited in the wild by CISA — ranked by ransomware use, then severity. Patch these before anything else.
This Reporting Window
- CVE-2026-16812 – Arista VeloCloud Orchestrator | CVSS 10.0 (CRITICAL) | AV: Network | EPSS 0.9% / 56th pct | Ransomware Use: No
- CVE-2025-68686 – Fortinet FortiOS | CVSS 5.9 (MEDIUM) | AV: Network | EPSS 1.3% / 67th pct | Ransomware Use: No
- CVE-2026-20316 – Cisco Secure Firewall Management Center (FMC) | CVSS 5.3 (MEDIUM) | AV: Network | EPSS 0.8% / 53th pct | Ransomware Use: No
Security News
Advisories, threat research, and incident reports from 12 sources across government, commercial research, and security journalism — prioritized by source credibility.
- CISA ICS AdvisoryAdvisory · today – Schneider Electric IGSS
View CSAF Summary Schneider Electric is aware of a vulnerability in its IGSS Definition module for the IGSS (Interactive Graphical SCADA System) product. The [IGSS](https://igss.schneider-electric.com/) product is a stat… - CISA ICS AdvisoryAdvisory · today – Rockwell Automation CompactLogix 5380 ControlLogix 5580 / 1756-EN4TR Communications Module
View CSAF Summary Successful exploitation of this vulnerability could allow an attacker to cause a denial-of-service condition. The following versions of Rockwell Automation CompactLogix 5380 ControlLogix 5580 / 1756-EN4… - CISA ICS AdvisoryAdvisory · today – Johnson Controls OpenBlue Employee
View CSAF Summary Successful exploitation of these vulnerabilities could allow an attacker to upload malicious files, execute stored cross-site scripting attacks, or inject arbitrary HTML content. The following versions … - SANS ISCResearch · yesterday – Apple Patches Everything (July 2026), (Wed, Jul 29th)
I am a bit late with this summary, but this week Apple released updates to all its operating systems and Safari. The Safari update, as usual, targets macOS prior to macOS 26. macOS updates covered the two older versions … - SANS ISCResearch · 2 days ago – AutoIT Payload Injector , (Tue, Jul 28th)
For a long time, AutoIT[1] has been pretty common in the malware ecosystem. Threat actors still use it because it's easy to write and powerful. Indeed, it can perform all the required actions to inject a pa… - Unit 42Incident · today – Chinese-Speaking Threat Actor Harnesses AI Models for Autonomous Cyberattacks
Unit 42 details a Chinese speaking threat actor combining autonomous AI scanning across seven vulnerabilities with manual exploitation. Read more. The post Chinese-Speaking Threat Actor Harnesses AI Models for Autonomous… - Unit 42Incident · 7 days ago – Russian Global Webmail Espionage
Unit 42 details a Russian cyberespionage campaign targeting Zimbra webmail servers using JavaScript injection to steal credentials. The post Russian Global Webmail Espionage appeared first on Unit 42 . - Sophos X-OpsResearch · 2 days ago – Chaos in Teams vishing
Attackers used Microsoft Teams vishing, custom malware, and remote access tools to facilitate ransomware deployment Categories: Threat Research Tags: Microsoft Teams, vishing, Ransomware, Chaos - Sophos X-OpsResearch · 3 days ago – 2607-secai
<p>What that means for Customer Protections&nbsp;</p> Categories: Threat Research, AI Research - The RecordIncident · today – Semiconductor chip titan Analog Devices reports data breach
In a filing for federal regulators, Massachusetts-based Analog Devices said intruders had exfiltrated data from its networks earlier this summer, but the scope of the incident is still under investigation. - The RecordNews · today – North Koreaâs Lazarus Group sharing tools with ransomware hackers, South Korean agencies warn
Cyberattack tools and infrastructure used by North Koreaâs Lazarus Group appear to have been shared with ransomware criminals targeting South Korean organizations â further evidence of deepening entanglement between … - Security Affairs (APT)Incident · 4 days ago – Hackers Hijack Hotel Wi-Fi to Steal Microsoft 365 Credentials
Hackers compromised hotel Wi-Fi gateways to redirect users to fake Microsoft 365 login pages and steal credentials. ReliaQuest’s threat research team just documented attackers compromising the Wi-Fi gateways at hot… - Security Affairs (APT)Incident · 5 days ago – Iran-Linked Actors Breach Are Targeting US Water and Energy Control Systems
US agencies warn Iran-linked actors are targeting internet-exposed water and energy control systems, risking disruption. Federal agencies updated their cybersecurity advisory this week: Iran-linked actors are inside Amer… - Security Affairs (Cybercrime)News · today – Cybercriminals Are Leveraging Autonomous AI Offensive Security Agents
Resecurity warns AI offensive agents are lowering hacking barriers, fueling an AI-driven race between attackers and defenders. Resecurity analyzed how autonomous offensive security agents such as T3MP3ST, Strix, CyberStr… - Security Affairs (Cybercrime)Incident · today – Analog Devices Discloses Data Breach After Unauthorized System Access
Chipmaker Analog Devices disclosed a data breach after detecting unauthorized access to systems on June 23. The investigation is ongoing. Semiconductor giant Analog Devices (ADI) disclosed a data breach following a cyber…
Ransomware Activity
Victim counts posted to ransomware group leak sites — use this to gauge which groups are most active and which sectors and regions are being targeted.
37 new victims posted today
7-day total: 230 via Ransomware.live
Infostealer Exposure: 17,915 employee credentials and 975,550 user credentials compromised via infostealer malware across victim organisations — indicating credential theft likely preceded these ransomware deployments.
Most Active Groups
Group Intelligence
- Qilin — Qilin ransomware was first observed in July of 2022. Qilin Ransomware is written in Golang and supports multiple encryption modes; all of which are controlled by the operator. Qilin actors practice double extortion – demanding payment for a decryptor, as well as for the non-release of stolen data.
- Crpxo — CRPxO is actively recruiting affiliates, offering:
🔹 70% revenue share
🔹 XMR/BTC payouts
🔹 Claimed payouts within 24 hours
🔹 $333 one-time affiliate access
Most Targeted Sectors
Top Countries
US (96), DE (12), GB (11), IN (10), BR (10)
Notable Incidents
- Universitatea de Vest „Vasile Goldiș” din Arad (Education · RO) — claimed by Qilin. N/A Press coverage →
- BH Security, LLC. (brinkshome.com) (Professional Services · US) — claimed by Shinyhunters. Over 4.9 million Salesforce records containing some PII was compromised. This is a final warning to reach out by 30 July 2026 before we leak along with several annoying (digital) problems that'll come your way. Make the … Press coverage →
- greenecountyga.gov (Government & Defense · US) — claimed by Incransom. Greene County, Georgia is a historic and scenic county located in the east-central "Lake Country" region of the state, roughly halfway between Atlanta and Augusta. Established in 1786 as Georgia's 11th county, it is wide… Press coverage →
- msgas.com.br (Energy & Utilities · BR) — claimed by Blackwater. customers' personal data, contract information, internal company data:
http://ucfhnoihzgx4wz4beyzfxnh46cs37r4zbq627xyctykpatruvmghbyqd.onion/s/7f89713825a4376e/ Press coverage → - Plitvička Jezera Nacionalni Park (Hospitality · HR) — claimed by Qilin. N/A Press coverage →
Vendor-Specific Risks
Vendors with confirmed KEV exploitation this week — the stacked bar shows how that exposure breaks down across exploited CVEs (red), critical CVEs to watch (orange), and news mentions (yellow). Prioritize patching vendors with the largest red segment.
Stay Ahead
Found this useful? Get the daily report in your reader.
Free. No account. No email. Follow in Feedly, Inoreader, or any RSS reader.